Skip to main content

Overview

Last updated: 18.06.2026·All documents current

Privacy isn't a checkbox. It's a commitment. Sally AI is built on the principle that your data belongs to you: it stays within the EU, primarily in Germany at Hetzner, is masked before any AI model ever touches it, and is never used to train or improve language models. We hold ourselves to the highest European data protection standards so you can focus on getting value from AI, without compromise.

Compliance & Certifications

GDPRGDPR
Compliant

Fully compliant with the EU General Data Protection Regulation. GDPR-compliant DPA under Art. 28 with every customer.

Germany HostingGermany Hosting
Active100% DE by end of July 2026

All data is stored in the EU, primarily in Germany at Hetzner. No third-country transfers, ever. From end of July 2026, exclusively in German data centers at Hetzner.

Data MaskingData Masking
Active

All personal data is masked before being processed by any language model. Identifiable information never reaches the AI.

ISO 27001ISO 27001
Certified

Certified to ISO 27001:2022 for information security management, part of our independently audited integrated management system. Full details on our ISO Certifications page.

ISO 14001ISO 14001
Certified

Certified to ISO 14001:2015 for environmental management. Full details and the downloadable certificate on our ISO Certifications page.

ISO 9001ISO 9001
Certified

Certified to ISO 9001:2015 for quality management. Full details and the downloadable certificate on our ISO Certifications page.

SOC 2SOC 2
Compliant

Service organization controls aligned with SOC 2 principles for security, availability, and confidentiality.

No AI Training🚫
Guaranteed

Your data is never used to train or improve language models, guaranteed contractually and technically.

DORA🛡️
Compliant

Sally AI meets the requirements of the Digital Operational Resilience Act (DORA) for financial-sector resilience.

⚖️
EU AI Act
Regulation (EU) 2024/1689
Risk Classification
Limited Risk
Transparency
Auto-notice in meeting chat
Data Masking
Before every LLM call
Declaration
Available for download
Full details →
Roadmap
Our path to GDPR & Compliance
Dec 2026Accessibility self-declaration (EN 301 549 / WCAG 2.1 AA)

Self-declaration on accessibility aligned with EN 301 549 and WCAG 2.1 AA, including the mandatory disclosures required by BITV and BFSG. Provides public-sector buyers and customers with elevated accessibility requirements a solid basis.

Sep 2026Network segmentation & dedicated bastion host

Network-level separation of administration traffic and compute workload networks, including a dedicated jump/bastion host (per BSI C5:2026, controls COS-02.01B, COS-05.01B, COS-05.02B).

Jul 2026Own LLM — fully independent of external AI providers

Launch of Sally's own large language model in production, replacing Azure OpenAI. Every step of inference happens inside our own infrastructure — no more dependency on external AI providers.

Jul 2026100% Germany-only infrastructure

All data exclusively in German data centers, with zero dependency on non-German EU regions.

May 2026✓ ISO 27001 certification

Information security is at the heart of Sally AI. Our certified ISMS to ISO 27001:2022, independently audited, backs our security promises with structured risk management and controls that protect your data end-to-end, not just on paper.


Security Controls

Infrastructure
  • AES-256 encryption at rest
  • TLS/SSL encryption in transit
  • ISO 27001-certified EU data centers
  • DDoS protection & rate limiting
  • Geo-redundant backups
Access & Authentication
  • Multi-factor authentication (MFA) on all systems
  • Role-based access control (RBAC)
  • Principle of least privilege
  • Full audit logging of all access
  • Tenant-level data separation
AI & Data Privacy
  • Personal data masked before any LLM processing
  • No AI training on customer data, ever
  • EU-region Azure OpenAI deployment
  • Bring Your Own LLM option available
  • On-premises storage option available
Processes & Organisation
  • DPA with every customer & all subprocessors
  • Regular employee security training
  • Incident notification to customer < 24 hours
  • Annual penetration tests by external security firms
  • DPIA per Article 35 GDPR
  • Regular internal security reviews

Completing the DPA: Two Options

RecommendedRequest online
1
Fill out the form: Enter your company details directly in the online form.
2
DPA is generated: Your personalized DPA is created automatically.
3
Sign digitally: You receive the DPA via email and can sign it directly online.
Complete manually
1
Download: Get the DPA in your preferred language.
2
Sign: Digitally or by hand. The signatory must be authorized to represent the company.
3
Email: Send the signed copy to privacy@sally.io. We countersign within 1–3 business days.

Documents & Resources

📄
Data Processing Agreement (DPA)

GDPR-compliant DPA under Art. 28, signed with every customer. Available in English and German.

Download DPA
🔒
Technical & Org. Measures (TOMs)

Our full technical and organizational security measures. Annex 1 of the DPA.

Download TOMs
🌐
Subprocessors List

All subprocessors with processing purpose and EU hosting location. Annex 3 of the DPA.

Download List

Contact

Data Protection Officer
Norton Engele